Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-34486

Опубликовано: 09 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS3: 7.5

Описание

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

РелизСтатусПримечание
devel

not-affected

10.1.54
esm-apps/noble

not-affected

code not present
esm-apps/resolute

not-affected

code not present
jammy

DNE

noble

not-affected

code not present
questing

not-affected

code not present
resolute

not-affected

code not present
upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

not-affected

11.0.21
esm-apps/resolute

not-affected

code not present
jammy

DNE

noble

DNE

questing

not-affected

code not present
resolute

not-affected

code not present
upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

not-affected

code not present
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps-legacy/xenial

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

not-affected

code not present
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needed

esm-infra-legacy/xenial

not-affected

code not present
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

ignored

end of life

Показывать по

РелизСтатусПримечание
devel

not-affected

9.0.117
esm-apps/bionic

not-affected

code not present
esm-apps/focal

not-affected

code not present
esm-apps/jammy

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-apps/resolute

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present
resolute

not-affected

code not present

Показывать по

EPSS

Процентиль: 99%
0.42627
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
nvd
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

CVSS3: 7.5
debian
4 месяца назад

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat du ...

CVSS3: 7.5
github
4 месяца назад

Apache Tomcat Missing Encryption of Sensitive Data vulnerability

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостатками шифрования конфиденциальных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 99%
0.42627
Средний

7.5 High

CVSS3